Rapid Edge Designs
UK Statutory & Data Protection Compliance

Privacy Policy

Last Updated & Effective Date: 3 October 2026 • Rapid Edge Designs Ltd

[Placeholder: Subject to final review by legal counsel before public launch]

This document defines the real operational privacy architecture and data processing practices of Rapid Edge Designs Ltd under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018. Formal statutory covenants remain subject to final verification by appointed legal counsel prior to general commercial launch.

1. Identity of Data Controller and Data Processor

Rapid Edge Designs Ltd is a private limited company incorporated in England & Wales under Company Registration Number 17486891, with its registered office located at 66 Paul Street, London, England, EC2A 4NA.

Data Controller Role

Rapid Edge Designs Ltd acts as a Data Controller for personal data collected directly from our business clients, prospective partners, and visitors to rapidedgedesigns.com. This includes business account setup, communications, and Bacs Direct Debit billing administration.

Data Processor Role

For customer inquiries, booking reservations, and contact submissions received through client websites hosted on our Website-as-a-Service (WaaS) platform, Rapid Edge Designs Ltd acts strictly as a Data Processor on behalf of the client pursuant to UK GDPR Article 28. The business client acts as the independent Data Controller.

Supervisory Authority Notification: Information Commissioner's Office (ICO) Registration: pending.

2. Information We Collect

Depending on your relationship with Rapid Edge Designs Ltd, we collect and process the following categories of personal data:

  • Business Client Account Details: Representative name, trading name, business registration number, business email address, UK telephone number, and registered or operating address.
  • Payment & Billing Data: Bank account holder name, sort code, last two digits of bank account number, and mandate reference IDs processed securely via our FCA-regulated payment partner, GoCardless Ltd, under the Bacs Direct Debit Scheme. We never store full bank credentials on our local servers.
  • Tenant Client Inquiries (As Processor): Name, email address, telephone number, and message content submitted by end-users requesting quotes or appointments through client websites.
  • Technical & Edge Diagnostic Logs: Anonymized or pseudo-anonymized IP addresses, browser user-agent strings, timestamps, and requested URI resources captured via Amazon CloudFront edge access logs for security monitoring, DDoS mitigation, and diagnostic uptime verification.

3. Lawful Bases for Processing (UK GDPR Article 6)

We process personal data only when an applicable lawful basis exists under Article 6 of the UK GDPR:

Contractual Necessity (Article 6(1)(b)):

Processing necessary to configure and deploy client websites, provision custom domain DNS, execute monthly maintenance routines, and collect agreed retainer subscriptions.

Legal Obligation (Article 6(1)(c)):

Retention of financial transaction records, invoices, and accounting ledgers in accordance with the Companies Act 2006, Finance Act 1998, and HMRC statutory tax regulations.

Legitimate Interests (Article 6(1)(f)):

Ensuring edge network security, mitigating automated bot abuse via AWS WAF and CloudFront, and diagnosing infrastructure availability.

4. Data Retention, Ephemeral Storage & Automated Purge

We enforce strict data minimization through automated infrastructure lifecycles:

90-Day PII TTL (Inquiries)

Pursuant to Architectural Decision Record (ADR 0007), customer inquiries submitted through client contact forms are automatically purged from our Amazon DynamoDB datastore 90 days after ingestion using native hardware TTL.

6-Year Statutory Billing Ledger

Under Companies Act 2006 s.388 and HMRC tax regulations (FA 1998 Sch 18), commercial billing records and Bacs Direct Debit payment history are retained for 6 years from the end of the financial year and are exempt from tenant purge routines (ADR 0011).

5. Sub-Processors and Data Residency

All core database instances and computing workloads reside in the United Kingdom (AWS London Region: eu-west-2). We engage the following vetted sub-processors:

Sub-ProcessorService ProvidedData ResidencySafeguard Mechanism
Amazon Web Services EMEA SARLCloud infrastructure, DynamoDB, S3, CloudFront CDN, WAFUnited Kingdom (London eu-west-2)AWS UK GDPR Addendum / ISO 27001
GoCardless LtdBacs Direct Debit mandate authorization and subscription billingUnited KingdomFCA-authorised Payment Institution
Resend Inc.Transactional email notification delivery for customer inquiriesUnited States / Global EdgeUK IDTA / Standard Contractual Clauses

6. Zero Tracking Cookies & PECR Compliance

Rapid Edge Designs Ltd does not deploy tracking cookies, advertising beacons, or third-party behavioral profiling pixels (such as Google Analytics or Meta Pixel). Because our site uses zero non-essential cookies, no intrusive cookie consent banner is mandated under the Privacy and Electronic Communications Regulations 2003 (PECR) / Schedule A1. For full technical details, consult our Cookie Policy.

7. Data Subject Rights & How to Contact Us

Under the Data Protection Act 2018 and UK GDPR, you have the right to request access to, rectification of, or erasure of your personal data, as well as the right to object to or restrict processing.

Exercising Your Rights:

To submit a Subject Access Request (SAR) or query our data protection practices, email our compliance team at:privacy@rapidedgedesigns.comor write to our registered office: Rapid Edge Designs Ltd, 66 Paul Street, London, England, EC2A 4NA.

Right to Lodge a Complaint:

You possess the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF• Tel: 0303 123 1113 • Website: ico.org.uk.